Resource Type: AWS > Bedrock AgentCore > Workload Identity
The Amazon Bedrock AgentCore Workload Identity resource represents a named principal referenced by agent runtimes, gateways, and credential providers for OAuth2 / resource-token issuance. Identities are lean (name, ARN, and an optional list of allowed OAuth2 return URLs).
Resource Context
Workload Identity is a part of the Bedrock AgentCore service.
Each Workload Identity lives under a Region.
Controls
The primary controls for AWS > Bedrock AgentCore > Workload Identity are:
Quick Actions
- Delete
- Delete from AWS
- Router
- Set Tags
- Skip alarm for Active control
- Skip alarm for Active control [90 days]
- Skip alarm for Tags control
- Skip alarm for Tags control [90 days]
- Update Tags
Category
In Your Workspace
- Controls by Resource Type report
- Policy Settings by Resource Type report
- Resources by Resource Type report
Developers
- tmod:@turbot/aws-bedrockagentcore#/resource/types/workloadIdentity
- tmod:@turbot/turbot#/resource/categories/iam
- turbot graphql resource --id "tmod:@turbot/aws-bedrockagentcore#/resource/types/workloadIdentity"
Get Resource- select * from guardrails_resource where resource_type_uri = 'tmod:@turbot/aws-bedrockagentcore#/resource/types/workloadIdentity';
- select * from guardrails_policy_setting where filter = 'resourceTypeId:"tmod:@turbot/aws-bedrockagentcore#/resource/types/workloadIdentity"';
- select * from guardrails_notification where resource_type_uri = 'tmod:@turbot/aws-bedrockagentcore#/resource/types/workloadIdentity' and notification_type in ('resource_updated', 'resource_created');
Get ResourceGet Policy Settings (By Resource ID)Get Resource Notification
Resource Type URI
Category URI
GraphQL
CLI
Steampipe Query